SC-300 · Question #361
You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings: - Require users to register when signing in: Yes - Number of methods required to…
The correct answer is D. an email to an address outside your organization. Option D is correct because Microsoft Entra SSPR supports sending a verification code or link to an external email address (one outside the organization) as a valid authentication method - this is explicitly listed among the supported SSPR methods alongside mobile app code…
Question
You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings:
- Require users to register when signing in: Yes
- Number of methods required to reset: 1
What is a valid authentication method available to users?
Options
- Aa Windows Hello PIN
- Ba smartcard
- Ca mobile app notification
- Dan email to an address outside your organization
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- D94% (31)
Explanation
Option D is correct because Microsoft Entra SSPR supports sending a verification code or link to an external email address (one outside the organization) as a valid authentication method - this is explicitly listed among the supported SSPR methods alongside mobile app code, mobile app notification, phone call, and SMS.
Why the others are wrong:
- A (Windows Hello PIN) is a device-bound authentication method used for signing into Windows; it is not a supported SSPR method in Microsoft Entra.
- B (Smartcard) is a certificate-based authentication method for sign-in scenarios, but it is not available as an SSPR reset method.
- C (Mobile app notification) - while the Microsoft Authenticator app is supported for SSPR, it works via an app code (TOTP), not a push notification; push notifications are used for MFA sign-in, not SSPR.
Memory tip: Think of SSPR methods as things you can use without being on a corporate device or network - external email, phone (SMS/call), and authenticator codes all fit that pattern. If the method requires corporate infrastructure (smartcard, Windows Hello) or is a push notification (MFA-specific), it won't apply to SSPR.
Topics
Community Discussion
No community discussion yet for this question.